Malware

Generic.BrResMon.1.E540F5A4 malicious file

Malware Removal

The Generic.BrResMon.1.E540F5A4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.E540F5A4 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:17160, 0.0.0.0:62909
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
k.modakenchina.com
s.modakenchina.com

How to determine Generic.BrResMon.1.E540F5A4?


File Info:

crc32: D413810B
md5: dde974639936b72e92484d0c7d7340a1
name: DDE974639936B72E92484D0C7D7340A1.mlw
sha1: b8f4157d9fe55ffef3a747535470033b08d058d6
sha256: d5f67c63e13f2d101be939ed821c697359866cf2b27a063d6e9f3fc4a0c02f68
sha512: cea5158107104c3e913f7846b0afa548949eab98a8469db66de7d463adbc3e7c130b1a152348b37862d5f29d91d834a8e9ac6cfce19e6b10fe8c8317f721a3f8
ssdeep: 3072:p/L9kJ1AG/tFOKMQq8mFbIGxPCISm7dI1EZS3DXSr:NG1A8tFXkZ1NSm7e1EZS3ur
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, ignomodoudeb
FileVersion: 10.1.10.11
ProductVersion: 10.1.10.11
Translation: 0x0809 0x04b0

Generic.BrResMon.1.E540F5A4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00526cba1 )
LionicTrojan.Win32.GandCrypt.tphU
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacDeepScan:Generic.BrResMon.1.E540F5A4
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39642
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00526cba1 )
Cybereasonmalicious.39936b
CyrenW32/S-c5d37cab!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCZP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Emotet-6447327-0
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
BitDefenderDeepScan:Generic.BrResMon.1.E540F5A4
NANO-AntivirusTrojan.Win32.Yakes.exynrl
MicroWorld-eScanDeepScan:Generic.BrResMon.1.E540F5A4
TencentWin32.Trojan.Generic.Wwof
Ad-AwareDeepScan:Generic.BrResMon.1.E540F5A4
ComodoTrojWare.Win32.NeutrinoPOS.C@7ise8z
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.dde974639936b72e
EmsisoftDeepScan:Generic.BrResMon.1.E540F5A4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Diple.bbxy
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.246DEC3
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Ursnif.KDS!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataDeepScan:Generic.BrResMon.1.E540F5A4
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeeGenericRXEB-KP!DDE974639936
MAXmalware (ai score=99)
VBA32TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.Bunitu
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GandCrypt!rB7PfXp2qRk
IkarusTrojan.Crypt
FortinetW32/Kryptik.GLKY!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.E540F5A4?

Generic.BrResMon.1.E540F5A4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment